Inside The Gentlemen Ransomware Leak: When the Hunter Becomes the Hunted
ID: ddedaf7f-dd5f-5cd8-ba24-241fbd35cb2b
STIX ID: report--ddedaf7f-dd5f-5cd8-ba24-241fbd35cb2b
Feed Name: SOCRadar Blog
Threat Score
**Executive summary:** The Gentlemen, a rapidly scaling RaaS operation active since mid‑2025, suffered a May 2026 backend breach that exposed server credentials, internal chat logs, affiliate rosters, ransom negotiation transcripts, tooling lists, exploited CVEs and victim data (hundreds of victims), revealing detailed TTPs, affiliate structure, and operational infrastructure that defenders can use to detect and mitigate ongoing ransomware activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
